CVE-2026-7734
MEDIUMosrg GoBGP SRv6 L3 Service prefix_sid.go SRv6L3ServiceAttribute.DecodeFromBytes denial of service
Title source: cnaDescription
A vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts the function SRv6L3ServiceAttribute.DecodeFromBytes of the file pkg/packet/bgp/prefix_sid.go of the component SRv6 L3 Service. Such manipulation of the argument data leads to denial of service. The attack may be performed from remote. Upgrading to version 4.4.0 will fix this issue. The name of the patch is f9f7b55ec258e514be0264871fa645a2c3edad11. You should upgrade the affected component.
References (6)
Core 6
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-360909 | osrg GoBGP SRv6 L3 Service prefix_sid.go SRv6L3ServiceAttribute.DecodeFromBytes denial of service
https://vuldb.com/vuln/360909
Signature, Permissions Required signature
permissions-required
VDB-360909 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/360909/cti
Third Party Advisory third-party-advisory
Submit #807581 | GoBGP 4.3.0 Infinite Loop
https://vuldb.com/submit/807581
Product product
https://github.com/osrg/gobgp/
Scores
CVSS v3
5.3
EPSS
0.0006
EPSS Percentile
17.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-404
Status
published
Products (5)
osrg/GoBGP
4.0
osrg/GoBGP
4.1
osrg/GoBGP
4.2
osrg/GoBGP
4.3.0
osrg/GoBGP
4.4.0
Published
May 04, 2026
Tracked Since
May 04, 2026